#StopRansomware: Phobos Ransomware

SUMMARY Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories…

Comments Off on #StopRansomware: Phobos Ransomware

Vulnerability Summary for the Week of February 19, 2024

High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info agronholm -- cbor2 cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC…

Comments Off on Vulnerability Summary for the Week of February 19, 2024

SVR Cyber Actors Adapt Tactics for Initial Cloud Access

How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known…

Comments Off on SVR Cyber Actors Adapt Tactics for Initial Cloud Access

Updated: Top Cyber Actions for Securing Water Systems

Today, CISA, the Environmental Protection Agency (EPA), and the Federal Bureau of Investigation (FBI) updated the joint fact sheet Top Cyber Actions for Securing Water Systems. This update includes additional…

Comments Off on Updated: Top Cyber Actions for Securing Water Systems

Vulnerability Summary for the Week of February 12, 2024

  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info wp_swings -- coupon_referral_program   Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program.…

Comments Off on Vulnerability Summary for the Week of February 12, 2024

Vulnerability Summary for the Week of February 5, 2024

  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info allegro_ai -- clearml Lack of authentication in all versions of the fileserver component of Allegro…

Comments Off on Vulnerability Summary for the Week of February 5, 2024

JetBrains Releases Security Advisory for TeamCity On-Premises

JetBrains released a security advisory to address a vulnerability (CVE-2024-23917) in TeamCity On-Premises. A cyber threat actor could exploit this vulnerability to take control of an affected system. CISA encourages…

Comments Off on JetBrains Releases Security Advisory for TeamCity On-Premises